8 ms·
Re: The Spirit of Free Software, or the Reality
- MichaelCrawford 11y ago127.0.0.1 www.google-analytics.com 127.0.0.1 ssl.google-analytics.com 127.0.0.1 www.hosted-pixel.com # I Swear I'm Not Making This Up On some but not all operating systems it's better to use 0.0.0.0. It's better to block it with a firewall but your aged grandmother doesn't know how to configure them. iOS and I expect Android have hosts files but you must jailbreak to edit them. On iOS you can do that with iFile from the Cydia store. iFile once cost money but it's free now.
- freshyill 11y agoMy Grandmother's a real ace when it comes to editing hosts.
- gkoberger 11y agoYour grandmother probably doesn't use Ice Weasel, and probably doesn't care it's making requests.
- magicalist 11y agoThis does absolutely nothing wrt the URLs in the linked email.
- pbiggar 11y agoThis is what happens when folks with a radically-non-mainstream view of privacy try to use an app built for mainstream folks by folks with slightly more mainstream opinions about privacy.
- tedunangst 11y agoIt's not obvious to me that "I want my browser to tell Google about every site I visit" actually is the mainstream view of privacy.
- iMerNibor 11y ago"Privacy Google maintains the Safe Browsing Lookup API, which has a privacy drawback: "The URLs to be looked up are not hashed so the server knows which URLs the API users have looked up". The Safe Browsing API v2, on the other hand, has the following privacy advantage: "API users exchange data with the server using hashed URLs so the server never knows the actual URLs queried by the clients". The Firefox and Safari browsers use the latter." https://en.wikipedia.org/wiki/Google_Safe_Browsing#Privacy https://en.wikipedia.org/wiki/Google_Safe_Browsing#Privacy
- deleted 11y ago[deleted]
- jonchang 11y agoFirefox's safebrowsing feature uses a separate cookie jar, so if you are logged into Google those cookies will never be sent via the safebrowsing API. Also, Firefox hashes the URL and compares the prefix of that hash to a master table downloaded from Google. If the URL matches a prefix in the table, Firefox requests all URLs that begin with that prefix hash. Google is never sent the full hashed URL.
- tedunangst 11y agoHeh. The next paragraph after that quote is: > Safe Browsing also stores a mandatory preferences cookie on the computer[9] which the US National Security Agency allegedly uses to identify individual computers for purposes of exploitation.[10] That may or may not be true, but must one be a radical to be concerned?
- nickodell 11y agoIt's true, but slightly misleading. If you open firefox and browse to a few sites, it will send that cookie. If you then take your computer down to the coffee shop and keep browsing, even if you don't log into anything, it will still send that cookie in the clear. There are other ways that the NSA can figure out a list of IP addresses you've been using, but this is 1) totally silent, and 2) is common to a lot of systems.
- im3w1l 11y agoIf Iceweasel is not hardline about freedom and privacy, what does it offer compared to vanilla Firefox? Edit: Since this is getting upvotes, I was wrong and pigeons is right.
- pigeons 11y agoThe sole purpose of Iceweasel is to not be subject to any restrictions (mozilla approval of changes) that may come with distributing trademarked "Firefox" software.
- deleted 11y ago[deleted]
- im3w1l 11y agoI looked into it further, and know I see where my confusion came from. [Debian] Iceweasel is a fork [from Firefox] with the following purpose : backporting of security fixes to declared Debian stable version. no inclusion of trademarked Mozilla artwork (because of #1 above) Beyond that, they will be basically identical. (quoting Roberto C. Sanchez post in debian-devel mailing list) But there was another Iceweasel, GNU Iceweasel. To avoid confusion with Debian Iceweasel, it has been renamed to GNU Icecat. GNU IceCat, formerly known as GNU IceWeasel,[3] is a free software rebranding of the Mozilla Firefox web browser distributed by the GNU Project. It is compatible with Linux, Windows, Android and OS X.[4] The GNU Project keeps IceCat in synchronization with upstream development of Firefox while removing all trademarked artwork. It also maintains a large list of free software plugins. In addition, it features a few security features not found in the mainline Firefox browser. This article is about Debian's Iceweasel, which is why my comment was wrong. https://wiki.debian.org/Iceweasel https://wiki.debian.org/Iceweasel https://en.wikipedia.org/wiki/GNU_IceCat https://en.wikipedia.org/wiki/GNU_IceCat
- iMerNibor 11y agoSo, from what I gathered it's just the favicons of the search engines, some mozilla country stuff (not sure why) and google safe browsing (which you can turn off and is a good feature for casual users) So what's the issue here? All this isnt really a problem and safe browsing is, in my opinion, even good for normal users.
- Manishearth 11y agoI'm pretty sure that these get requests don't even fetch with cookies, so fingerprinting is probably impossible here. The most info they can get is "hey, this ip uses Firefox". Harmless in itself. It can be compounded with more info to track someone, but all of this info already contains IP/browser info so this doesn't help at all.
- dclusin 11y agoI recall reading something on the internet that IP + browser fingerprint is good enough to unique identify a large number of people. Has this changed or otherwise untrue?
- faitswulff 11y agoA quick click here convinced me that this is still the case: https://panopticlick.eff.org/ https://panopticlick.eff.org/
- kbrosnan 11y agoThis is a handful of GET requests for images. You would need a page to fingerprint. The site could get an IP, likely the user agent. Safe browsing requests are sandboxed from all the other Google cookies.
- scottw 11y agoYou sure those are images? All we know for certain is that those are GET requests.
- PhantomGremlin 11y agoThese browsers are all constantly accessing many sites. Here's[1] a comment I posted a month ago about Firefox. The summary is here's (at minimum) what Firefox accesses when it starts up as a Guest in OS X, and this is after I unchecked a bunch of boxes: self-repair.mozilla.org snippets.cdn.mozilla.net search.yahoo.com location.services.mozilla.com www.mozilla.org tiles.services.mozilla.com safebrowsing.google.com aus4.mozilla.org Try it yourself as Guest. But make sure that Parental Controls are on. That way OS X will popup these sites and ask permission. Firefox is unusable w/o opting in all of these. [1] https://news.ycombinator.com/item?id=9743799 https://news.ycombinator.com/item?id=9743799
- hendry 11y agoAt Webconverger I've been working on whittling these leaking issues down, by wiresharking Firefox, e.g. https://github.com/Webconverger/webconverger-addon/issues/42 https://github.com/Webconverger/webconverger-addon/issues/42 https://github.com/Webconverger/webconverger-addon/issues/41 https://github.com/Webconverger/webconverger-addon/issues/41 https://github.com/Webconverger/webconverger-addon/issues/43 https://github.com/Webconverger/webconverger-addon/issues/43 Though with things like https://bugzilla.mozilla.org/show_bug.cgi?id=1100304 https://bugzilla.mozilla.org/show_bug.cgi?id=1100304 and anti-features like http://dustri.org/b/firefox-youre-supposed-to-be-in-my-pocket-not-the-other-way-around.html http://dustri.org/b/firefox-youre-supposed-to-be-in-my-pocke... you got to wonder if Mozilla has stopped caring about privacy.
- provemewrong 11y agoIt's interesting, especially since Firefox currently heavily uses "privacy" as their selling point: >Committed to you, your privacy and an open Web [1] >We’ve always designed Firefox to protect and respect your private information. That’s why we’re proud to be voted the Most Trusted Internet Company for Privacy. [1] >When it’s personal, choose Firefox. [2] [1]: https://www.mozilla.org/en-US/firefox/desktop/ https://www.mozilla.org/en-US/firefox/desktop/ [2]: https://www.mozilla.org/en-US/firefox/new/ https://www.mozilla.org/en-US/firefox/new/
- Qantourisc 11y agoI also wonder how much work it would be to make a version with these striped out. Replacing functionality with a NOOP, is often not that hard.
- okasaki 11y agoThe problem is that it's a big responsibility. You can't just do it once and dump it on the internet. It has to be kept up to date with the latest Firefox versions, and it has to have prompt releases (within a day). You also need to be absolutely sure that your changes aren't creating more problems than they're fixing.
- otherusername2 11y agoThe whole shrugging off and downplaying of issues like this are exactly the reason the internet is complete shit when it comes to security. Why, after all the exploits, insecure software and bad decisions, can people still not see that they can't anticipate everything? For instance, here's a scenerio I can easily envision: The NSA strongarms Ebay into letting them sniff TCP connections to their favicon, combines the TCP fingerprint with the browser useragent to uniquely identify you from perhaps millions of other users. Geolocate your IP to determine where you are and bam they know all about you they need to know. Tin-foil hat? Of course. Plausible? Totally. Doable? Absolutely. They don't need to be perfect, just good enough.
- sethish 11y agoWait, we all realize these are grabbing the favicons for the bookmarks right? This list of .iso's reads to me like a list of default bookmarks.